Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Lhaplus LHA Extended Header Handling Buffer Overflow Vulnerability

Lhaplus is prone to a buffer-overflow vulnerability in its LHA extended header handling routine.

A successful attack can allow a remote attacker to corrupt process memory by triggering an overflow condition when Lhaplus reads the extended header in an LZH file.

This vulnerability reportedly affects version 1.52 (Japanese) of Lhaplus. Previous versions may also be vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus